The POST /PamProviders method creates a new PAM PAM (Privileged Access Management): Controls privileged access by vaulting credentials, enforcing least-privilege/just-in-time access, rotating secrets, and auditing sessions. Across Keyfactor products, PAM protects diverse sensitive operations and secrets—for example certificate stores and CA credentials—via built-in or third-party providers; external integrations are delivered as custom PAM extensions (several published on Keyfactor’s public GitHub). provider. This method returns HTTP 200 OK on a success with details for the new provider.
 PAM (Privileged Access Management): Controls privileged access by vaulting credentials, enforcing least-privilege/just-in-time access, rotating secrets, and auditing sessions. Across Keyfactor products, PAM protects diverse sensitive operations and secrets—for example certificate stores and CA credentials—via built-in or third-party providers; external integrations are delivered as custom PAM extensions (several published on Keyfactor’s public GitHub). provider. This method returns HTTP 200 OK on a success with details for the new provider.
This method has two available versions. Keyfactor recommends using the newer method when possible. For more information about versioning, see Versioning.
Version 2 of the POST /PamProviders method has been redesigned to remove references to PAM associations with areas and containers.
Table 604: POST PamProviders v2 Input Parameters
| Name | In | Description | 
|---|---|---|
| Name | Body | Required. A string indicating the name of the PAM provider. This name is used to identify the PAM provider throughout Keyfactor Command. Important:  The name you give to your PAM provider in Keyfactor Command must match the name of the PAM provider as referenced in the manifest.json file (see Installing Custom PAM Provider Extensions). | 
| Provider Type | Body | Required. An object containing details about the provider type for the provider.  | 
| Provider Type Param Values | Body | Required in some cases.  An array of objects containing the values for the provider types specified by ProviderTypeParam.  Example:  When creating or updating a PAM provider for Delinea local to Keyfactor Command, your request body might look like (where the ProviderType ID and ProviderTypeParam Ids and Names are retrieved using GET /PamProviders/Types):
						 Copy  | 
| Remote | Body | A Boolean indicating whether the PAM provider is local to the Keyfactor Command server (false) or local to the orchestrator (true). The default is false. | 
Table 605: POST PamProviders v2 Response Data
| Name | Description | 
|---|---|
| Id | An integer indicating the Keyfactor Command reference ID for the PAM provider. This ID is automatically set by Keyfactor Command. | 
| Name | A string indicating the name of the PAM provider. This name is used to identify the PAM provider throughout Keyfactor Command. | 
| Provider Type | An object containing details about the provider type for the provider.  | 
| Provider Type Param Values |  An array of objects containing the values for the provider types specified by ProviderTypeParam.  | 
| Remote | A Boolean indicating whether the PAM provider is local to the Keyfactor Command server (false) or local to the orchestrator (true). The default is false. | 
Version 1 of the POST /PamProviders method includes the same capabilities as version 2 except it includes references to the deprecated parameters related to the area of Keyfactor Command to which the PAM provider applies.
Table 606: POST PamProviders v1 Input Parameters
| Name | In | Description | 
|---|---|---|
| Name | Body | Required. A string indicating the name of the PAM provider. This name is used to identify the PAM provider throughout Keyfactor Command. Important:  The name you give to your PAM provider in Keyfactor Command must match the name of the PAM provider as referenced in the manifest.json file (see Installing Custom PAM Provider Extensions). | 
| Provider Type | Body | Required. An object containing details about the provider type for the provider.  | 
| Provider Type Param Values | Body | Required in some cases.  An array of objects containing the values for the provider types specified by ProviderTypeParam.  Example:  When creating or updating a PAM provider for Delinea local to Keyfactor Command, your request body might look like (where the ProviderType ID and ProviderTypeParam Ids and Names are retrieved using GET /PamProviders/Types):
						 Copy  | 
| Remote | Body | A Boolean indicating whether the PAM provider is local to the Keyfactor Command server (false) or local to the orchestrator (true). The default is false. | 
Table 607: POST PamProviders v2 Response Data
| Name | Description | 
|---|---|
| Id | An integer indicating the Keyfactor Command reference ID for the PAM provider. This ID is automatically set by Keyfactor Command. | 
| Name | A string indicating the name of the PAM provider. This name is used to identify the PAM provider throughout Keyfactor Command. | 
| Area | An integer indicating the area of Keyfactor Command the provider is used for. This is considered deprecated and may be removed in a future release. | 
| Provider Type | An object containing details about the provider type for the provider.  | 
| Provider Type Param Values |  An array of objects containing the values for the provider types specified by ProviderTypeParam.  | 
| Remote | A Boolean indicating whether the PAM provider is local to the Keyfactor Command server (false) or local to the orchestrator (true). The default is false. | 
| Secure Area Id | An integer indicating the Keyfactor Command reference ID for the certificate store container the PAM provider is associated with, if any. This is considered deprecated and may be removed in a future release. | 
 An API is a set of functions to allow creation of applications. Keyfactor offers the Keyfactor API, which allows third-party software to integrate with the advanced certificate enrollment and management features of Keyfactor Command. endpoints can be called and results returned. It is intended to be used primarily for validation, testing and workflow
 An API is a set of functions to allow creation of applications. Keyfactor offers the Keyfactor API, which allows third-party software to integrate with the advanced certificate enrollment and management features of Keyfactor Command. endpoints can be called and results returned. It is intended to be used primarily for validation, testing and workflow A workflow is a series of steps necessary to complete a process. In Keyfactor Command, it refers to the workflow builder, which allows you to automate event-driven tasks such as when a certificate is requested, revoked or found in a certificate store. development. It also serves secondarily as documentation for the API. The link to the Keyfactor API Reference and Utility is in the dropdown from the help icon (
 A workflow is a series of steps necessary to complete a process. In Keyfactor Command, it refers to the workflow builder, which allows you to automate event-driven tasks such as when a certificate is requested, revoked or found in a certificate store. development. It also serves secondarily as documentation for the API. The link to the Keyfactor API Reference and Utility is in the dropdown from the help icon ( ) at the top of the Management Portal page next to the Log Out button.
) at the top of the Management Portal page next to the Log Out button.Was this page helpful? Provide Feedback